GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
2,853 advisories
Filter by severity
nanoid: Integer Overflow or Wraparound
High
CVE-2026-73086
was published
for
nanoid
(npm)
Sep 1, 2026
pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml
High
GHSA-vx52-2968-3vc6
was published
for
pnpm
(npm)
Sep 1, 2026
pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project
High
GHSA-2rx9-3g3h-c2jv
was published
for
pnpm
(npm)
Sep 1, 2026
Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM
High
CVE-2026-73089
was published
for
browserslist
(npm)
Sep 1, 2026
Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats)
High
CVE-2026-73088
was published
for
browserslist
(npm)
Sep 1, 2026
MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials
High
GHSA-3f6p-5ww8-9rcr
was published
for
mysql2
(npm)
Sep 1, 2026
Socket.IO: Engine.IO WebTransport SID DoS
High
CVE-2026-59724
was published
for
engine.io
(npm)
Aug 31, 2026
MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`
High
CVE-2026-55215
was published
for
mariadb
(npm)
Aug 28, 2026
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
High
CVE-2026-55641
was published
for
9router
(npm)
Aug 28, 2026
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
High
CVE-2026-55638
was published
for
9router
(npm)
Aug 28, 2026
SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed
High
CVE-2026-54606
was published
for
suneditor
(npm)
Aug 26, 2026
@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys
High
CVE-2026-54511
was published
for
@logtape/syslog
(npm)
Aug 26, 2026
Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`
High
CVE-2026-54356
was published
for
@budibase/server
(npm)
Aug 26, 2026
@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key
High
CVE-2026-55604
was published
for
@arikusi/deepseek-mcp-server
(npm)
Aug 25, 2026
consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file write
High
CVE-2026-55609
was published
for
consciousness-explorer
(npm)
Aug 25, 2026
Whistle vulnerable to path traversal
High
CVE-2026-55629
was published
for
whistle
(npm)
Aug 25, 2026
Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
High
CVE-2026-55596
was published
for
@platejs/media
(npm)
Aug 25, 2026
browse-mcp has an arbitrary file write via unconfined download and state paths
High
CVE-2026-55557
was published
for
browse-mcp
(npm)
Aug 25, 2026
urllib's cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakage
High
CVE-2026-55553
was published
for
urllib
(npm)
Aug 25, 2026
pickem vulnerable to terminal escape-sequence injection via unsanitized item text
High
GHSA-8qx3-8gm5-9cj2
was published
for
pickem
(npm)
Aug 25, 2026
Keystone vulnerable to `graphql.maxTake` bypass with negative `take`
High
CVE-2026-63421
was published
for
@keystone-6/core
(npm)
Aug 21, 2026
Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors
High
CVE-2026-61824
was published
for
defuddle
(npm)
Aug 21, 2026
Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
High
CVE-2026-63462
was published
for
unleash-server
(npm)
Aug 21, 2026
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
High
GHSA-ghvf-qf6h-g8x5
was published
for
@nocobase/server
(npm)
Aug 20, 2026
node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS
High
CVE-2026-54156
was published
for
node-opcua
(npm)
Aug 20, 2026
ProTip!
Advisories are also available from the
GraphQL API